Browse Source

Added warning about flatpages and untrusted users.

Mariusz Felisiak 1 năm trước cách đây
mục cha
commit
571bab9887
1 tập tin đã thay đổi với 7 bổ sung0 xóa
  1. 7 0
      docs/ref/contrib/flatpages.txt

+ 7 - 0
docs/ref/contrib/flatpages.txt

@@ -164,6 +164,13 @@ For more on middleware, read the :doc:`middleware docs
 How to add, change and delete flatpages
 =======================================
 
+.. warning::
+
+    Permissions to add or edit flatpages should be restricted to trusted users.
+    Flatpages are defined by raw HTML and are **not sanitized** by Django. As a
+    consequence, a malicious flatpage can lead to various security
+    vulnerabilities, including permission escalation.
+
 .. _flatpages-admin:
 
 Via the admin interface